CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,381 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 1 of 88
- CVE-2024-3400CRITICALCVSS 10.0EG 10.0⚠ KEV2024-04-12
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated atta…
- CVE-2025-10035CRITICALCVSS 9.8EG 10.0⚠ KEV2025-09-18
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- CVE-2024-51378CRITICALCVSS 9.8EG 10.0⚠ KEV2024-10-29
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secM…
- CVE-2026-8037CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-04
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endp…
- CVE-2024-12356CRITICALCVSS 9.8EG 9.8⚠ KEV2024-12-17
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
- CVE-2024-55956CRITICALCVSS 9.8EG 9.8⚠ KEV2024-12-13
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autor…
- CVE-2023-20887CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-07
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
- CVE-2023-1671CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-04
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
- CVE-2016-20017CRITICALCVSS 9.8EG 9.8⚠ KEV2022-10-19
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
- CVE-2022-29303CRITICALCVSS 9.8EG 9.8⚠ KEV2022-05-12
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
- CVE-2021-45382CRITICALCVSS 9.8EG 9.8⚠ KEV2022-02-17
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826…
- CVE-2021-27561CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-15
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
- CVE-2021-36260CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-22
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious co…
- CVE-2021-35395CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-16
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs a…
- CVE-2021-35394CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-16
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command inje…
- CVE-2021-1498CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
- CVE-2020-2509CRITICALCVSS 9.8EG 9.8⚠ KEV2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the …
- CVE-2020-25506CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-02
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
- CVE-2018-19949CRITICALCVSS 9.8EG 9.8⚠ KEV2020-10-28
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; …
- CVE-2010-5330CRITICALCVSS 9.8EG 9.8⚠ KEV2019-06-11
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP pro…
- CVE-2016-1555CRITICALCVSS 9.8EG 9.8⚠ KEV2017-04-21
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote atta…
- CVE-2015-4852CRITICALCVSS 9.8EG 9.8⚠ KEV2015-11-18
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to …
- CVE-2012-1823CRITICALCVSS 9.8EG 9.8⚠ KEV2012-05-11
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitra…
- CVE-2007-3010CRITICALCVSS 9.8EG 9.8⚠ KEV2007-09-18
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
- CVE-2005-2773CRITICALCVSS 9.8EG 9.8⚠ KEV2005-09-02
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
- CVE-2023-2868CRITICALCVSS 9.4EG 9.4⚠ KEV2023-05-24
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the …
- CVE-2024-21887CRITICALCVSS 9.1EG 9.1⚠ KEV2024-01-12
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the a…
- CVE-2020-4006CRITICALCVSS 9.1EG 9.1⚠ KEV2020-11-23
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
- CVE-2026-42271CRITICALCVSS 8.8EG 9.0⚠ KEV2026-05-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…
- CVE-2025-4008CRITICALCVSS 8.8EG 9.0⚠ KEV2025-05-21
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an e…
- CVE-2023-39780CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-11
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the simil…
- CVE-2023-33538CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-07
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
- CVE-2023-1389CRITICALCVSS 8.8EG 9.0⚠ KEV2023-03-15
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the countr…
- CVE-2022-36804CRITICALCVSS 8.8EG 9.0⚠ KEV2022-08-25
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8…
- CVE-2021-22899CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-27
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
- CVE-2020-25079CRITICALCVSS 8.8EG 9.0⚠ KEV2020-09-02
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
- CVE-2019-0541CRITICALCVSS 8.8EG 9.0⚠ KEV2019-01-08
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explo…
- CVE-2017-6327CRITICALCVSS 8.8EG 9.0⚠ KEV2017-08-11
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target proc…
- CVE-2015-2051CRITICALCVSS 8.8EG 9.0⚠ KEV2015-02-23
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
- CVE-2026-22719CRITICALCVSS 8.1EG 9.0⚠ KEV2026-02-25
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assis…
- CVE-2016-3081CRITICALCVSS 8.1EG 9.0⚠ KEV2016-04-26
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
- CVE-2016-6367CRITICALCVSS 7.8EG 9.0⚠ KEV2016-08-18
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
- CVE-2010-4345CRITICALCVSS 7.8EG 9.0⚠ KEV2010-12-14
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_direc…
- CVE-2022-27924CRITICALCVSS 7.5EG 9.0⚠ KEV2022-04-21
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
- CVE-2024-12987CRITICALCVSS 7.3EG 9.0⚠ KEV2024-12-27
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The mani…
- CVE-2024-3273CRITICALCVSS 7.3EG 9.0⚠ KEV2024-04-04
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the com…
- CVE-2025-29635CRITICALCVSS 7.2EG 9.0⚠ KEV2025-03-25
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, trigg…
- CVE-2024-9380CRITICALCVSS 7.2EG 9.0⚠ KEV2024-10-08
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
- CVE-2022-40765CRITICALCVSS 6.8EG 9.0⚠ KEV2022-11-22
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of…
- CVE-2023-20118CRITICALCVSS 6.5EG 9.0⚠ KEV2023-04-13
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. …
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →